Industry Research · September 2026

The State of Email & DNS Security Across Australian Organisations

4,633 Australian organisations across five sectors, assessed using publicly observable DNS and registry data, September 2026.

45%
No published DMARC record
74.0%
No enforcing DMARC posture
4,633
Organisations across five sectors

This report examines the published DNS, email-authentication, and registry records of 4,633 Australian organisations across five sectors. The headline finding: 45% have no published DMARC record at all, meaning there is no policy published by the domain owner telling receiving mail systems how to handle messages that fail domain authentication, the mechanism behind email spoofing. Most still publish an SPF record, but without a DMARC policy, there's nothing instructing receiving systems what to do when a message fails that check.

No published DMARC record, by sector

SectorOrganisations checkedNo DMARC record
Health2,75648.2%
Trades56245.2%
Real Estate59844.1%
Legal30539.3%
Finance41229.4%
Pooled across all five sectors: 45% (2,087 of 4,633), reported as the headline figure because it counts every organisation checked exactly once, not an average of the five sector percentages.
Methodology, in brief

Non-intrusive, DNS and registry data only

Every check in this study is a DNS lookup, a Certificate Transparency log query, or a public WHOIS/RDAP lookup: the same information any member of the public can query about any domain. No email was sent, no website was probed, no mail server was contacted. The population was sourced from OpenStreetMap business listings with an associated website, nationwide: every organisation identifiable from that public dataset was checked, not a drawn sample. Data was collected between 23 and 30 September 2026.

Want the full report?

The full report includes the complete per-sector breakdown (SPF, DKIM, CAA, dangling MX records), DMARC enforcement posture by sector, cross-check correlations, the full methodology, and sampling limitations.

Request a copy